HNHacker News
TopNewBestAskShowJobs

laurenstill

80 karma · joined June 2, 2013

Health IT developer
submissionscomments
laurenstill··on Secure Messaging Scorecard
TigerText also seems noticeably absent.
laurenstill··on Doctors Tell All, and It’s Bad
This year is the first for physician attestation for MUS2, give it some time. Chances are you will have to actively ask for login information if you are seeing a doctor in a small(er) private practice, as it's likely not a core priority of their EHR software (think 'it's there because it has to be, not because we actually expect anyone to use it'). Of my 6 doctors, 3 have EHRs with patient portals, but none of them are populated with encounter data or visit notes; two don't use an EHR and one is associated with UCSF and uses Epic, so I get MyChart.

Last month I was trying to get a copy of my MRI from UCSF, but their cd burner on the PACS was down. They are participants in RSNA image share so patients can opt to import scans into a portal but it took me 3 people in the radiology library before finding someone who knew anything about it.

laurenstill··on Open-source HIPAA compliance company policies
Said it before, say it again, thank you Mark. I wonder what our industry would look like if we spent less time reinventing the wheel all day long and more time working on the problems we love.
laurenstill··on The Internet of Someone Else’s Things
So glad you mentioned this. I'm not sure what IoT for consumers looks like beyond text notifications from my smoker, but there are pretty big ramifications on the healthcare scene, and networking disparate units in a meaningful way. Just an example, I've seen several cardiology projects that track a patient from EMT to discharge while providing actionable insight. It's one of the few things in medicine I'm actually hopeful about.
laurenstill··on White House Names Google’s Megan Smith the Next CTO of the US
I do find it mildly interesting that both the CTO and National Coordinator for Health IT roles recently went to females for the first time. Both are incredibly deserving on their own merit, and I can't wait for the time when this isn't the first thing to be mentioned.
laurenstill··on Ask HN: Salaries for remote depend on location?
I'm the opposite. I live in SF but work for a AZ company, and am kinda getting the shaft on that. It's something I've accepted (for now) since I really couldn't ask for a better job.
laurenstill··on 6.0 Northern California earthquake
Used to work in Florida, and it's a pretty noticeable difference in DR/Continuity strategy to what I work with now out here (SF). For the first 24 hours after Hurricane Ivan it was completely focused on: Are our employees safe; do they have water/food; what medical aid is needed; how can we get blankets and cots into our office so our employees have a place to sleep tonight? All the roads are washed out, there was no real in/out of town for a week, no power to our main DC for 3. Having redundancy in Chicago and Virginia didn't really mean shit when we couldn't get key people to those data centers to run them full steam.

The end result was a high reliance on contract employees at the fail-overs, and a real appreciation for the human element.

laurenstill··on Show HN: Aptible – Deployment platform to automate HIPAA compliance
This is what I'm most curious about. The technical/security side is only 1/3 of HIPAA, how do you turnkey the remainder? How do you scale/automate preforming repeat RAs, etc, across different clients?
laurenstill··on Show HN: Aptible – Deployment platform to automate HIPAA compliance
Thanks for having a bug bounty program, far too infrequent in healthIT.

Can you expand more on "generate all of the documentation, audit logs, and explanatory materials you need to demonstrate compliance with every aspect of HIPAA."?

Also, with QSM requirements for the vast majority of other healthcare regulations, you need to explicitly address them in documentation to be compliant. Does Aptible address this, or only HIPAA?

laurenstill··on Ask HN: What's the most annoying thing about your job?
Not my 9-5, but I end up in a number of meetings to plan for meetings with some of the consulting work I do, and then after 6 months it all seems futile when they don't actually run with or implement any of the recommendations or strategies I laid out for them. Why bother asking (and paying) for my advice if you're just going to do what you want anyways?
laurenstill··on Google Co-Founders on Healthcare: “Thanks, But No Thanks”
...and the hospitals are using credit card data in their population management models. Oh, you've stopped by the liquor store 3 times this week and now presenting with pancreatitis? Sorry, you are now in our "at risk" billing class.

Just cause I'm feeling particularly paranoid today.

laurenstill··on Google Co-Founders on Healthcare: “Thanks, But No Thanks”
Never said privacy shouldn't be protected, only that it's not exactly valued by BOTH sides of the equation (and of course, YMMV). Up until recently (Omnibus rule), HIPAA had little practical power in that department from both an audit perspective and a fine/mediation perspective. The largest fine levied? It was for inadequate patient access to their own health information, not a security breach.

And even with the new rule, there are currently no regulations surrounding de-identified PHI being used for marketing purposes, research, or sold for whatever other purposes. So now you have data wharehousers like IMS spinning up software dev depts with the specific goal of harvesting patient data.

As far as identity vs membership vs attribute disclosure, I linked to a good study below.

I find it interesting that there are more comments in the average HN healthcare-related thread than on any of the recent NPRM. Hell, there are more comments here than people who actually showed up for FDASIA.

I support regulation in a lot of cases, and feel that that FDA took a reasonable approach to the recent mobile medical device guidelines. What I, and pretty much everyone else (other than the AMA) rails against is the indiscriminate flip flopping of what regulations, standards, etc will be required, and on what time horizon.

laurenstill··on Google Co-Founders on Healthcare: “Thanks, But No Thanks”
You both may be interested in this paper: Publishing data from electronic health records while preserving privacy: A survey of algorithms

http://webcache.googleusercontent.com/search?q=cache:1gHT-y0...

laurenstill··on Google Co-Founders on Healthcare: “Thanks, But No Thanks”
I'd argue they are at disadvantage. Small startups can't eat the cost of spending 2 years developing for a particular standard just to have it changed on the due date.
laurenstill··on Google Co-Founders on Healthcare: “Thanks, But No Thanks”
Most people don't worry about their data privacy, or else they wouldn't be on FB, take those buzzfeed quizzes, etc.

The P in HIPAA stands for Portability. At it's heart, the act was supposed to guarantee patients have access to their health information, not bring health data liquidity to it's knees.

This is Jonathan Bush, of Athena, testifying (read: ranting) a couple weeks ago about regulations and innovation in healthcare. The big take away is that healthcare specifically sets these rules with incredibly high barriers of entry, and then at the last minute does a complete 180. We've seen it every step of the way with the EHR incentive program, CEHRT, ICD-10, payment reimbursement, etc. https://www.youtube.com/watch?v=CekfvGDiab8

laurenstill··on Fatal Dose – Radiation Deaths linked to AECL Computer Errors (1994)
Compliance officer for a med device company, can confirm. Even vendor audits don't look at code, just SOPs and spreadsheets documenting that you have the processes in place to log the shit out of everything.
laurenstill··on Dumb.domains
I'm ashamed, but I grabbed shitty.recipe.

I put most of my bachelor frog friends to shame, so maybe it will be fun.

laurenstill··on Better Raises $5M To Be Your Personal Health Advocate
With the rise in deductibles, and still no formal structure for telehealth reimbursement through insurance companies, more people will start sourcing out other options for low cost alternatives. $50/mont isn't for me, or a lot of people, but I wouldn't be so quick to dismiss it, especially on family plans.
laurenstill··on Healthcare.gov users told to change passwords following Heartbleed flaw
I did some poking around when Heartbleed first was disclosed publicly, and while hc dot gov may not be directly affected, a number of the state exchanges are. Not seeing this reported, anywhere.
laurenstill··on Ask HN: What are the best April Fools of 2014?
Personally, I was a fan of Eisen forsaking open access.

http://www.michaeleisen.org/blog/?p=1580

laurenstill··on New RFS – Breakthrough Technologies
Scrolled down to healthcare, and wow, clearly no domain experience. Spend another year researching and listening first.
laurenstill··on Recruitment Process for a Google Site Reliability Engineer
Fair enough, and I agree to an extent. But when I got that packet of prep material, I froze. I may go down that road again in the near future, but I want to be mindful of thresholds.
laurenstill··on Recruitment Process for a Google Site Reliability Engineer
Thanks. I've turned down a couple interviews knowing I'd bomb at least one, didn't want that on my perm Google Record. It's nice to know it's not just me, and also there's redemption.
laurenstill··on Ask HN: Best OSS Projects for Beginning Contributors
I would focus on larger, well known established projects covering a variety of interests. For me, personally, I wont get much out of just pushing code or documentation to a project I don't care about. Second to that, is not working with asshole. I'm not sure how I would script that.

OpenMRS was my first true OSS introduction, even though at the time I knew nothing about java. It's in my field of choice, and large enough I got some decent mentorship and appropriate projects. Doesn't hurt that they also regularly participate in GNOME/FOSSOPW, so I knew there would be people interesting and willing to mentor.

laurenstill··on Recruitment Process for a Google Site Reliability Engineer
That meshes with the interview process my SO went through, at Google, for an SRE role. Similarly, they said he could code in any language (his preference is C) but the interviewer preferred python. 45 min to whiteboard in C, you better have a backup set of markers.

His feedback after all was said and done was "brush up on your scripting languages."

laurenstill··on How We Make Trello
This is great and all, but I really wish I knew why they won't make the audit logs accessible to users. If someone has a hack for this, I'm all ears.

Need it for compliance documentation.

laurenstill··on Ask HN: How effective have the job posts on HN been?
My current job I got through HN, in addition to a number of interviews. Not a YC Co though.
laurenstill··on Anyone familiar with www.updox.com?
It's built on the Direct protocol, so I'm not seeing why it's particularly special. Direct, secure messaging and V/D/T is a requirement for the 2014 MUS2....
laurenstill··on Ask HN: I've designed a smart defibrillator how can I kickstart it
http://www.medstartr.com/ built by Alex Faire, may be a better fit but it's a pretty small audience. Have you gone over the project with a regulatory fine-tooth comb?
laurenstill··on Ask HN: How to increase self-discipline as a self-employed person?
A while back I quit my 9-5 and started working on a number of consulting/projects on a rotating basis.

One of the things I did in addition to having dedicated work space and clear boundaries was to assign projects on a per-day basis. Most of my contracts are longer-term grant projects where I'm committed to 10 hr/week or so.

Monday = local hardware project Tues = DirectTrust Wens = Dignity Health etc...

I make sure the companies I'm working with understand what their dedicated day is, and have a clear time line of deliverables. This gives me enough urgency on a day to day basis to prevent falling into the trap of "taking care of it later."

I also have a set time for general email first thing in the morning, in addition to break times where I can cook, clean and work on dinner. I know some would say that's a horrible break, but I'd rather do it mid day that at 9pm (as I would when I commuted).

The other thing was removing the tv in the office. I was surprised and how distracting it was, considering I never paid attention to it. I now use use music as background/white noise.

And I can't recommend a pet partner enough, just lock them out during concalls least you earn a reputation of being "that cat lady in policy."

Page 1 of 3Next →